Search docs
Find a page, section or endpoint

Get started

Authentication

The two services you call, their base URLs, and the tokens each one takes.

Services and base URLs#

There are two services you talk to:

ServiceUsed forBase URL
Events collectorSending events, from the browser or your servershttps://<collector-host>/v1
Control planeConfiguration (event types, metrics, segments) and reads (profiles, members)https://api.breeze.in/cdp/control-plane

Set your own base URLs, tenant and workspace on Your values, and every example on the site uses them.

Collector authentication#

EventsEndpointTokenIdentifiers accepted
Server-side/events/authenticatedAuthorization: Bearer $COLLECTOR_TOKENAll, including email and phone. These events are trusted and can link identities.
Browser/eventsNoneDevice-level only (cookie, device_id), because anyone can call it.

Control-plane tokens#

Every request carries Authorization: Bearer <token>. There are two kinds of token:

TokenFormatWho has itCan do
Tenantcpt_<id>.<secret>Your platform or admin service (issued by the BreezeIQ team)Everything in the tenant: configuration writes, all workspaces, minting workspace tokens
Workspacecpw_<id>.<secret>Dashboards and apps of one workspaceRead-only: that workspace's profiles, segments and members, plus the tenant's event types and metric definitions

A token can never see another tenant's data, and a workspace token can never see another workspace's data (403). Mint workspace tokens with the Tokens API.

Check a token#

GET /v1/whoami tenant or workspace token

Returns what the token is for.

bash
curl "https://api.breeze.in/cdp/control-plane/v1/whoami" -H "Authorization: Bearer $BREEZEIQ_TOKEN"

Next#